PT-2002-1435 · Microsoft · Internet Explorer+1
Published
2002-07-03
·
Updated
2018-10-30
·
CVE-2002-0372
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Media Player versions 6.4 and 7.1
Media Player for Windows XP
Description
The issue allows remote attackers to bypass Internet Explorer's security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the Internet Explorer cache.
Recommendations
For Microsoft Windows Media Player versions 6.4 and 7.1, consider disabling the execution of .wma files until a patch is available.
For Media Player for Windows XP, restrict access to the executable .wma media files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer
Windows Media Player